ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | x86_64 |
| Full analysis: | https://app.any.run/tasks/29c023b9-ba61-4d7d-a88d-f4b5eee13104 |
| Verdict: | Malicious activity |
| Threats: | A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet. |
| Analysis date: | August 21, 2024, 18:47:36 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | application/x-executable |
| File info: | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped |
| MD5: | 9B0DAF70BC6EE71FF95EB36F10D0C337 |
| SHA1: | E500DFB8CA56B084226D9B49F99553000BD0EDA8 |
| SHA256: | E38146B8AF6197F91E45D7745F8DA0B86EB998CF17101FB0504521B26F6B02DC |
| SSDEEP: | 768:nF98/zcVt4Lx84LpswKYSEWseUV25/oO/sxR01TbYc8kBRiOgPFNJ0tdTJFI:nz8/zcVt4LxhpsRYndd2SElLBRkXq |
| .o | | | ELF Executable and Linkable format (generic) (100) |
|---|
| CPUArchitecture: | 64 bit |
|---|---|
| CPUByteOrder: | Little endian |
| ObjectFileType: | Executable file |
| CPUType: | AMD x86-64 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 12931 | /bin/sh -c "sudo chown user /tmp/x86_64\.o && chmod +x /tmp/x86_64\.o && DISPLAY=:0 sudo -iu user /tmp/x86_64\.o " | /bin/sh | — | any-guest-agent |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12932 | sudo chown user /tmp/x86_64.o | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12933 | chown user /tmp/x86_64.o | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12934 | chmod +x /tmp/x86_64.o | /usr/bin/chmod | — | sh |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12935 | sudo -iu user /tmp/x86_64.o | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12936 | /tmp/x86_64.o | /tmp/x86_64.o | — | sudo |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12937 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | x86_64.o |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12938 | /tmp/x86_64.o | /tmp/x86_64.o | — | x86_64.o |
User: user Integrity Level: UNKNOWN | ||||
| 12939 | (sd-pam) 64.o | /tmp/x86_64.o | x86_64.o | |
User: user Integrity Level: UNKNOWN | ||||
| 12941 | fusermount3 -o rw,nosuid,nodev,fsname=portal,auto_unmount,subtype=portal -- /run/user/1000/doc | /usr/bin/fusermount3 | — | fusermount3 |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 13178 | ibus-daemon | /var/lib/gdm3/.config/ibus/bus/b82edf789d4944789b773e6aeadf24e8-unix-1024 (deleted) | text | |
MD5:DFF449D13239C0A3D44856882BA194C7 | SHA256:8CF5DBCEEE0E92936DE3F58859B47463F70F6D500A4A6F839586F158AB9A88BE | |||
| 13123 | whoopsie | /var/lib/whoopsie/whoopsie-id (deleted) | text | |
MD5:E703EEEE37B13C3F2BA103A45507287A | SHA256:FB5D398C4DE8E23E16ADBCE21ADBA7ED48563334ABDFD472CE7AF0B061B48E7C | |||
| 12942 | apport | /var/log/apport.log | text | |
MD5:342FABA2F61CD5754431643E50DCCCBE | SHA256:081EC32DE909D2AC1297CA404BA9244418DE88CFF40F6549FE8AC3FF70C9A575 | |||
| 13472 | gvfsd-metadata | /var/lib/gdm3/.local/share/gvfs-metadata/root | binary | |
MD5:0743F105309AA646B43ECF796DC27CA3 | SHA256:901AD658325B78BEACC64D215D0B57F103B8ED7779F8A758EDB799306F2204F8 | |||
| 13339 | ibus-daemon | /var/lib/gdm3/.config/ibus/bus/b82edf789d4944789b773e6aeadf24e8-unix-wayland-0 | text | |
MD5:23722E6822B267A9FB43FB9239AA9441 | SHA256:751741B7342D3252B146DFD0314B440B1D34C2FA4C441EFBF90FB0812E6E9B31 | |||
| 13177 | gnome-session-binary | /var/lib/gdm3/.local/share/icc/edid-d566d177510e5f6427207727888b1a0b.icc | binary | |
MD5:2C6496A2A9166020ABC007AED12842A8 | SHA256:09576ACBAE4D98DEC7602B60108C67EE4A2BC59CEB09C10A60798242A2500BA2 | |||
| 13178 | ibus-daemon | /var/lib/gdm3/.config/ibus/bus/b82edf789d4944789b773e6aeadf24e8-unix-wayland-0 (deleted) | text | |
MD5:DFF449D13239C0A3D44856882BA194C7 | SHA256:8CF5DBCEEE0E92936DE3F58859B47463F70F6D500A4A6F839586F158AB9A88BE | |||
| 13178 | ibus-daemon | /var/lib/gdm3/.cache/ibus/bus/registry | binary | |
MD5:CE7083E92ED00B1959FF72E00711E4A2 | SHA256:623BB8AF942F2A779A020D301F2AEDFBAF4725A6708344A1B0F556A34C6A7BC9 | |||
| 13072 | dconf-service | /home/user/.config/dconf/user | bs | |
MD5:0F8F5F34459960ED99B0E76C6B9DE783 | SHA256:791CEE653E0E3D5A7A467775642074685531DFBAFF4405315C360F6220CB8104 | |||
| 13339 | ibus-daemon | /var/lib/gdm3/.config/ibus/bus/b82edf789d4944789b773e6aeadf24e8-unix-1024 | text | |
MD5:23722E6822B267A9FB43FB9239AA9441 | SHA256:751741B7342D3252B146DFD0314B440B1D34C2FA4C441EFBF90FB0812E6E9B31 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.97:80 | http://connectivity-check.ubuntu.com/ | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 91.189.91.49:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.17:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | unknown |
— | — | 91.189.91.97:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | unknown |
— | — | 212.102.56.178:443 | odrs.gnome.org | Datacamp Limited | DE | unknown |
12939 | x86_64.o | 185.196.9.5:51237 | fdh32fsdfhs.shop | Simple Carrier LLC | US | unknown |
485 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
485 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
fdh32fsdfhs.shop |
| unknown |
api.snapcraft.io |
| whitelisted |
195.100.168.192.in-addr.arpa |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
12939 | x86_64.o | Malware Command and Control Activity Detected | ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) |